Slashdot Mirror


Civil Servant Watching Porn At Work Blamed For Government Malware Outbreak (techcrunch.com)

An anonymous reader quotes a report from TechCrunch: A U.S. government network was infected with malware thanks to one employee's "extensive history" of watching porn on his work computer, investigators have found. The audit, carried out by the U.S. Department of the Interior's inspector general, found that a U.S. Geological Survey (USGS) network at the EROS Center, a satellite imaging facility in South Dakota, was infected after an unnamed employee visited thousands of porn pages that contained malware, which downloaded to his laptop and "exploited the USGS' network." Investigators found that many of the porn images were "subsequently saved to an unauthorized USB device and personal Android cell phone," which was connected to the employee's government-issued computer. Investigators found that his Android cell phone "was also infected with malware." The findings were made public in a report earlier this month but buried on the U.S. government's oversight website and went largely unreported.

104 of 180 comments (clear)

  1. EROS center?! by Anonymous Coward · · Score: 5, Funny

    The jokes write themselves!

    1. Re:EROS center?! by HarrySquatter · · Score: 1

      Those cheeky bastards!!!

    2. Re:EROS center?! by CosineHamster · · Score: 3, Funny

      Poor guy,he didn't search for porn long enough ; with enough hits on EROS; he would have found his way back to his own company.

    3. Re:EROS center?! by Thud457 · · Score: 1
      --

      the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff

    4. Re:EROS center?! by Scarletdown · · Score: 1

      You are not the only one to take note.

      To quote Buck Murdock (Airplane II: The Sequel), "Irony can be very ironic."

      --
      This space unintentionally left blank.
  2. Re:Single Rogue Host by guruevi · · Score: 1

    Wanna bet it was Windows based?

    --
    Custom electronics and digital signage for your business: www.evcircuits.com
  3. I bet by Revek · · Score: 1, Offtopic

    He go a promotion. Its not like they fire employees.

    1. Re:I bet by Revek · · Score: 1

      Nope, not offtopic. The problem with these public organizations is that they are allowed to do these things due to the fact they are rarely fired for them. Its almost impossible to get fired from a government job. This person will most likely get a little slap on the wrist and after a year or so be promoted and or receive a raise. The IT in their organization will most likely not face any penalty for not having secured their network and the devices operating on it. They talk about a blacklist of sites when they should be talking about a whitelist of allowed sites. I wonder if there is any data out there on how many people have been fired from the USGS?

    2. Re:I bet by arth1 · · Score: 3, Insightful

      They talk about a blacklist of sites when they should be talking about a whitelist of allowed sites.

      While this sounds nice in theory, in practice it is very hard to implement in a way that works and doesn't just hinder work. The people who administer the whitelist are not going to know what is needed for every job function. Nor will they have the capacity to monitor every whitelisted object to ensure that it remains safe. (One of the whitelisted sites might start serving ads proxied through their server - ads which aren't safe.)
      And for the users, requesting sites being added to a whitelist as needed can delay entire teams for days on end. What do you mean, we cannot download the schematics for the microcontroller we just discovered a problem with until it's added to a whitelist? And when it delays a high level manager who needs to look at a web site of a potentially new supplier or customer, the whitelist system will be gone.

    3. Re:I bet by Revek · · Score: 2

      I admit its not easy on the front end but you can easily get a good start by logging sites visited for a month and start with that. I've helped with the implementation of a white list at a few businesses and after a month or two its just a matter of maintenance.

    4. Re: I bet by Revek · · Score: 1

      Yeah, its called a typo. You should look that up.

    5. Re:I bet by NicBenjamin · · Score: 1

      At a business. Where everyone works in the same industry, and needs the same sites. My emplyers (Home Depot and H and R Block) would generate very different whitelists.

      If you're talking about the government the scale of required sites goes up exponentially. A single IRS office will probably need access to most of the finance sites H and R Block uses, plus all the sites Home Depot uses (might be auditing a contractor and need to find out how many boxes of nails are needed for a $50k expense to be justified), etc.

    6. Re:I bet by Revek · · Score: 1

      Its obvious that a whitelist would be specific to the business. It depends on weather you want you're employees to be able to access the whole of the internet. One eye doctor had us lock it down until they literally couldn't access anything unrelated to the job. She maintains the list herself and since it was installed none of her machines have become infected. On a larger scale it would require someone to work that desk full time but it would have the benefit of reducing this types of breach. You don't have to have a sysadmin to maintain it. You can train almost anyone to manage the list once its configured. You talk about cost but whats the cost of having unrestricted internet access in a large organization?

    7. Re:I bet by NicBenjamin · · Score: 1

      I didn't actually bring up cost. I brought up the scale of he whitelist, and the difficulty of administering it, but not the cost. This is the Federal government, there are literally millions of users, so any costs would be trivial on a per-user basis. The problem is creating some system that will actually whitelist the right websites for the right offices. A single small business does like one thing, for one segment of the market. The government does almost everything.

      Knowing the Feds, what you'd end up with is some interestingly-acronymed government department to do all the work. Other government agencies would spend a significant amount of time arguing with interestingly-acronymed-ones about what's on the whitelist. For example, just think of the sites required if a DEA Agent in Reno has to figure out whether a shipment of garden gnomes is cover for cocaine.

      A government-wide black-list would make more sense, because it's much less likely some rando Federal employew\e will have a need for a porn site or something,

  4. Not the only one at blame by Somebody+Is+Using+My · · Score: 5, Interesting

    The porn-watcher might have been the patient-zero of this outbreak, but I think as much if not more blame needs be laid at the feet of the IT staff that allowed the malware to get as far as it did. Limit user privileges, lock down access ports and use secure operating systems and the damage would not have been as severe; it might only have been limited to that single user's machine.

    But that sort of thinking would require a costly revamping of the entire computer infrastructure, so better to put the blame on a single user, who could just as easily have gotten the malware from an ad on a perfectly legitimate site. Fortunately, he was viewing porn (naked bodies entwined together! The most evil threat America has ever faced!) so it's easy to throw him to the wolves.

    1. Re:Not the only one at blame by lgw · · Score: 4, Insightful

      use secure operating systems

      Let me know when you find one. All browsers are vulnerable to something. Every OS has privilege excalation exploits and zero-days.

      Or were you just thinking "don't use Windows XP"? Yeah, I think everyone gets that now.

      so better to put the blame on a single user, who could just as easily have gotten the malware from an ad on a perfectly legitimate site. Fortunately, he was viewing porn (naked bodies entwined together! The most evil threat America has ever faced!) so it's easy to throw him to the wolves.

      Paid porn sites have damn good security, and are about the safest place on the web. The problem is the sites that come up when you google for porn (SEO malware sites), plus the ad networks used by free porn sites.

      To your point: an ad blocker would probably have prevented this, along with the default behavior of most browsers to block known malware sites.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    2. Re:Not the only one at blame by coofercat · · Score: 2

      Here in the UK, the government makes sure the potential infection is huge so it makes all that work to protect them from it worth the investment. https://www.telegraph.co.uk/ne...

    3. Re:Not the only one at blame by Bite+The+Pillow · · Score: 4, Insightful

      His manager, who didn't realize thus guy is spending a lot of time not working

      The network support, who didn't notice high band with use and try to figure if it was legit

      His coworkers who almost certainly knew he wasn't working

    4. Re:Not the only one at blame by arth1 · · Score: 1

      Every OS has privilege excalation exploits

      There are OSes with no privilege separation, and thus no privilege escalation, and thus no privilege escalation exploits.

      Of course, that's not the type of operating systems an end-user would use, but still, your "every" is wrong.

    5. Re:Not the only one at blame by geekmux · · Score: 2, Insightful

      The porn-watcher might have been the patient-zero of this outbreak, but I think as much if not more blame needs be laid at the feet of the IT staff that allowed the malware to get as far as it did. Limit user privileges, lock down access ports and use secure operating systems and the damage would not have been as severe; it might only have been limited to that single user's machine.

      But that sort of thinking would require a costly revamping of the entire computer infrastructure, so better to put the blame on a single user, who could just as easily have gotten the malware from an ad on a perfectly legitimate site. Fortunately, he was viewing porn (naked bodies entwined together! The most evil threat America has ever faced!) so it's easy to throw him to the wolves.

      The porn-watcher might have been the patient-zero of this outbreak, but I think as much if not more blame needs be laid at the feet of the IT staff that allowed the malware to get as far as it did. Limit user privileges, lock down access ports and use secure operating systems and the damage would not have been as severe; it might only have been limited to that single user's machine.

      I do agree with you regarding the IT policies that are severely lacking, but I'll believe there was an actual "outbreak" when the evidence presents itself. Neither TFS or TFA really says anything about the extent of this "outbreak" or the true damage that was caused, which tends to turn this entire article into nothing more than sensationalist bullshit. In fact, if you read the actual report, it states quite clearly that a single computer was found to have malware present, and it "exploited the USGS' network." with zero additional detail.

      But that sort of thinking would require a costly revamping of the entire computer infrastructure, so better to put the blame on a single user, who could just as easily have gotten the malware from an ad on a perfectly legitimate site. Fortunately, he was viewing porn (naked bodies entwined together! The most evil threat America has ever faced!) so it's easy to throw him to the wolves.

      Speaking of sensationalism, let's put aside the Americanized moral arguments here. Porn in the workplace is unprofessional at best and offensive and damaging at worst. That's common sense, and regardless of country. And there's more that just a good chance this infection was caused by that activity given the sheer volume of that activity, so it's hardly innocent activity no matter your moral stance or acceptance of pornography.

    6. Re: Not the only one at blame by LordWabbit2 · · Score: 1

      It's not only intel CPU's, ARM have their own issues as well. From an article about Spectre and meltdown.
      "In particular, we have verified Spectre on Intel, AMD, and ARM processors."

      --
      There are three kinds of falsehood: the first is a 'fib,' the second is a downright lie, and the third is statistics.
    7. Re:Not the only one at blame by lactose99 · · Score: 1

      Paid porn sites have damn good security, and are about the safest place on the web. The problem is the sites that come up when you google for porn (SEO malware sites), plus the ad networks used by free porn sites.

      Never really thought about it before but this is a damn good point. Too bad pay-for-porn doesn't market it as such.

      --
      Fully licensed blockchain psychiatrist
    8. Re:Not the only one at blame by CosineHamster · · Score: 1

      Operating Systems with no privilege separations? By that; do you mean operating systems where everyone is an administrator? That doesn't seem like a very good solution to preventing privilege escalation exploits. That's like saying "We don't worry about prisoners escaping to masquerade as guards! Everyone here is a guard already! "

    9. Re:Not the only one at blame by Anonymous Coward · · Score: 1

      Don't blame IT so quickly. "Scientists" utterly rage at any attempt to "control" they're usage of computer resources. Having local admin is common place and expected from the user base, and supported by management. Even content filtering tends to be a "taboo", again also supported by management who are often or were scientists themselves.

    10. Re:Not the only one at blame by arth1 · · Score: 2

      There are some older operating systems like DOS where users did have full control, but there are also modern operating systems where there is no privilege separation, like microcontroller operating systems. Your kitchen scales don't need to prevent privilege escalation exploits.
      (Although it would be a good hack to have the scales report too high weights of anything healthy and too low weights of anything unhealthy, slowly increasing the risks of death for the users.)

    11. Re:Not the only one at blame by lgw · · Score: 1

      Windows and IE just don't provide that level of control

      Windows lets you lock down just about anything via GPO. IE is being end-of-lifed, but you did have decent control over it. The big problem IE always had was lack of a common ad-blocker to force people to use (there were some, but none free).

      --
      Socialism: a lie told by totalitarians and believed by fools.
    12. Re:Not the only one at blame by Tablizer · · Score: 1

      manager [didn't realize this guy] is spending a lot of time not working

      Not necessarily. He/she could be an efficient worker who does in 3 hours what most do in 8. I've met some like that.

      Normally such a person would go to the private sector instead, but maybe they valued "play time" over money.

    13. Re:Not the only one at blame by lgw · · Score: 1

      hile no browser is completely secure, EVERYTHING is more secure than I.E./Edge.

      Edge is definitely more secure than Firefox. Pay attention the the Slashdot stories on hacking events and the like: IE and Firefox are being excluded as "too easy", while Chrome and Edge are harder targets. It's not 1998 any more, or even 2008.

      most everything is more secure than Windows

      That stopped being true with Vista, which was a long time ago now. XP sucked because in practice most people ran as local admin, and had admin privileges. Vista was much like Ubuntu: you get a pop-up whenever you need to elevate to admin/root. It's not 1998 any more, or even 2008.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    14. Re:Not the only one at blame by thegarbz · · Score: 1

      at the feet of the IT staff that allowed the malware to get as far as it did.

      Why are we talking about malware? How about the IT staff that allowed someone to visit "thousands" of porn sites without being flagged down for disciplinary measures. I'm willing to bet that this happened over quite a period of time.

    15. Re:Not the only one at blame by Zontar+The+Mindless · · Score: 1

      The press could have written "Government Malware Outbreak caused by web browsing", but no, they had to violate someone's privacy in passing. It's like writing "car accident on Main Street, the faulty driver was on his way to an extramarital affair". Why do reporters do this?

      Ex-reporter here to inform you that, if it's in a police report, it's not private.

      --
      Il n'y a pas de Planet B.
    16. Re:Not the only one at blame by aberglas · · Score: 1

      Or his manager may have decided the less work he does the less damage he can do.

      Or his manager liked watching porn on his computer.

    17. Re:Not the only one at blame by NicBenjamin · · Score: 1

      And while no operating system is completely secure, most everything is more secure than Windows (which has very little to do with its market dominance; its security is like Swiss cheese) or MacOS (which sacrifices a lot of security to make it shiny).

      Yes, Linux is WAY more security than both of them combined, but Javascript and Intel-based CPU's are the major vectors for concern nowadays. Both of them significantly negate all operating system security, and should be relegated to the shitcan of history.

      You're exaggerating. Back in the days of the "I'm a Mac"/"I'm a PC" commercials Apple was absolutely right to mock the fuck out of Windows security. It sucked. But these days almost all the holes are gone, and with Windows Defender you don't even really need Windows Anti-Virus software anymore. Which is just like OS X.

      As for the rest of "most everything," I respectfully a couple of clusters of Unixen used primarily by Sysadmin/High Geek types better be more secure then the shit us hoi polloi use.

  5. Yeah, this happens. Not just in the USG either. by Da+w00t · · Score: 4, Informative

    If you work computer security for any company of decent size, you're gonna discover someone surfing porn. Most times we give folks the benefit of a doubt the 1st time in case it's some porn ad something on an otherwise "okay" site (gray, but not really a policy violation), but once a pattern of porn surfing is discovered, it usually results in someone getting written up, potentially ending with them losing their job.

    Don't do this at work. You're not on your personal computer, it could be a shared computer (ewwww), and it's not your network. There's always someone watching to the benefit of the company, not you. It makes for an awful work environment for the people in the office, and can bring in malware. There's a joke I heard, of people clicking on the Yes/Accept/Install buttons ... "do I have porn yet?" [click] "do I have porn yet?" [click]. Lots of malware comes down in the form of a "video codec" or plugin you need to watch the media. It's just awful.

    --

    da w00t. mtfnpy?
  6. You did notice where he worked? by Anonymous Coward · · Score: 1

    "The EROS Center..." Oh, can irony get any better than this??!!

  7. Re:Single Rogue Host by cayenne8 · · Score: 1, Insightful

    Wanna bet it was Windows based?

    Wanna bet that since the person is a civil servant, that even after being caught, will still NOT be able to be fired?

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  8. “G” stands for Geological by 93+Escort+Wagon · · Score: 5, Funny

    But this dude apparently thought he worked for the United States Gynecological Survey.

    --
    #DeleteChrome
    1. Re: “G” stands for Geological by LordWabbit2 · · Score: 4, Funny

      Well at least he was hard at work.

      --
      There are three kinds of falsehood: the first is a 'fib,' the second is a downright lie, and the third is statistics.
    2. Re: “G” stands for Geological by 93+Escort+Wagon · · Score: 1

      I was going to reply with *rimshot* but then realized that might not be the best choice, given the context.

      --
      #DeleteChrome
    3. Re:“G” stands for Geological by Deep+Esophagus · · Score: 1

      First they'll erect a new firewall to guard against repeated penetration. Then they're going to take a long, hard look at employees' computer usage patterns. Anyone caught will face stiff punishment. And if you think you'll escape detection, you'd best disabuse yourself of that notion.

  9. Re:Single Rogue Host by Opportunist · · Score: 4, Insightful

    Wanna bet that he will be? You need a scapegoat after something like that, after all, and he's neither a politician nor a CEO.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  10. Re:Happens probably a lot by Opportunist · · Score: 1

    In my experience (with more than a decade in IT security), the weakest link is that CEO secretary that curiously needs to bypass the corporate content filter and also needs for some godawful reason admin access on her PC, despite the fact that she can't turn on the machine without causing a security incident.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  11. Re:Yeah, this happens. Not just in the USG either. by mark-t · · Score: 1

    If you work computer security for any company of decent size...

    And just how many people is that, precisely? 20? 50? 100? 1000?

  12. How? Why? by CustomSolvers2 · · Score: 1

    I am seriously considering the option of becoming a public servant and this information seems quite useful. Note to myself: when visiting porn sites at work, never download anything! LOL.

    Seriously, who downloads an executable from a porn site?! Part of the pathetically-nonsensical spam I am getting lately includes pretty crappy messages saying that I have to pay because they have recorded me watching porn? That otherwise they would destroy my reputation!! (I guess that they are planning to firstly build me a good reputation. LOL). By ignoring its overall nonsensical essence ("you can increase your available time by writing ++ in the calculator of your computer"!!), the first idea coming to my mind was precisely why would anyone download a piece of malware (not a video) from a porn site with the huge number of available alternatives where you don't need to do anything of this sort? I mean... this is at least what someone from my church told me. LOL.

    --
    Custom Solvers 2.0 = Alvaro Carballo Garcia = varocarbas.
    1. Re:How? Why? by freeze128 · · Score: 1

      You have never heard of a drive-by download?

    2. Re:How? Why? by CustomSolvers2 · · Score: 1

      You have never heard of a drive-by download?

      You mean something being downloaded to your computer without your consent or any kind of warning? Is this possible?

      --
      Custom Solvers 2.0 = Alvaro Carballo Garcia = varocarbas.
    3. Re:How? Why? by ahodgson · · Score: 1

      There are multiple announced vulnerabilities per month that allow this to happen. Mostly in Flash the last few years, but also in image decoders, sound decoders, and web browsers in general.

      Software security sucks.

    4. Re:How? Why? by CustomSolvers2 · · Score: 1

      There are multiple announced vulnerabilities per month that allow this to happen. Mostly in Flash the last few years, but also in image decoders, sound decoders, and web browsers in general.

      Quite scary stuff. In any case, you have still to be in the wrong place with the wrong tools (what usually means obsolete or not updated or not particularly good software) and to perform some wrong actions (even by assuming that a malicious application can be downloaded without your permission, it would still need to be run either by the user or by other application/SO what would imply one further layer of insecurity/negligence). Just visiting a shady website doesn't seem enough to provoke what is described here, not even in the most unfortunate scenario.

      --
      Custom Solvers 2.0 = Alvaro Carballo Garcia = varocarbas.
    5. Re:How? Why? by CustomSolvers2 · · Score: 1

      With "application/SO", I really meant "application/OS". FYI, SO is the Spanish version of OS.

      --
      Custom Solvers 2.0 = Alvaro Carballo Garcia = varocarbas.
  13. Re:public shaming by media by aitikin · · Score: 1

    So now slashdot has brought it to the front to publicly shame the individual?

    You must be new here...

    --
    "Don't meddle in the affairs of a patent dragon, for thou art tasty and good with ketchup." ~ohcrapitssteve
  14. Re:Yeah, this happens. Not just in the USG either. by Anonymous Coward · · Score: 1

    If you work computer security for any company of decent size...

    And just how many people is that, precisely? 20? 50? 100? 1000?

    2.

  15. Re:Single Rogue Host by Kiaser+Zohsay · · Score: 2

    Wanna bet they used IE 6 on XP to support some gawd-awful "legacy system" built by a low bidder back in the 90's?

    --
    I am not your blowing wind, I am the lightning.
  16. Re:Happens probably a lot by Kiaser+Zohsay · · Score: 1

    or other non job web use.

    Like, oh, say, Slashdot?

    --
    I am not your blowing wind, I am the lightning.
  17. Mr Anderson... by bill.pev · · Score: 1

    "I'd like to share a revelation that I've had during my time here. It came to me when I tried to classify your species and I realized that you're not actually mammals. Every mammal on this planet instinctively develops a natural equilibrium with the surrounding environment but you humans do not. You move to an area and you multiply and multiply until every natural resource is consumed and the only way you can survive is to spread to another area. There is another organism on this planet that follows the same pattern. Do you know what it is? A virus. Human beings are a disease, a cancer of this planet. You're a plague and we are the cure."

  18. So? by Murdoch5 · · Score: 1

    Surely his computer was running Quebes OS (or something similar), with the USB ports disabled. If this wasn't the case, why not?

  19. Watch porn by freeze128 · · Score: 1

    What else is there to do in South Dakota?

  20. Re: Single Rogue Host by Anonymous Coward · · Score: 1

    This is why you don't make all government computers openly connect to one another, or else some jerk-off (being literal here) infects your military/etc through some gardening branch of government.

  21. Re:Yeah, this happens. Not just in the USG either. by DNS-and-BIND · · Score: 2

    There are people out there who watch porn. I don't mean rub one out and close the window. No, they watch for hours and hours. They get addicted. They can't stop. Watching at work? Of course. Alcoholics drink at work, drug addicts are high at work, why wouldn't porn addicts watch porn at work?

    --
    Shutting down free speech with violence isn't fighting fascism. It IS fascism!
  22. now if there are stuck on old IE ActiveX may admin by Joe_Dragon · · Score: 1

    now if there are stuck on some old IE ActiveX software then users may admin to get work done.

  23. It's 2018 and the report suggests a blacklist? by schwit1 · · Score: 1

    "Investigators recommended that USGS enforce a “strong blacklist policy” of known unauthorized websites and “regularly monitor employee web usage history.”

    WHITELIST FFS. Not perfect but infinity better than a blacklist, also know as wack-a-mole.

    1. Re:It's 2018 and the report suggests a blacklist? by thegarbz · · Score: 1

      WHITELIST FFS.

      Or better yet, just turn off their internet complete. But on a more serious note, white-listing the internet is a recipe for disaster. A far better solution is to generate a blacklist and then flag up people who hit one of the blacklisted sites for further surveillance.

      Blacklisting allows the internet to still be a usable resource. Whitelisting just pisses off your workers at best or cripples your productivity (depending on the work you do) at worst.

  24. Re:Happens probably a lot by arth1 · · Score: 1

    A reasonable amount of non-work at work makes the employees more content, and content workers is usually a plus.
    It should of course be reasonable, but if you expect people to work like slaves for hours straight with no amount of non-work activity interspersed, expect malcontents and burn-outs.
    Fifteen minutes of shopping or news reading or something a couple of times a day might be acceptable. Hours on end, not so much.

  25. Lax network security. by gerald.edward.butler · · Score: 1

    But, Oh noes! The BOGEY-MAN PORN is to blame. What a crock! How do you know it wasn't from sports sites, shopping sites, joke sites, running your mouth sites? No, it has to be the BOGEY-MAN PORN!

    The #MeToo movement is a collective witch-hunt that is not interested in justice for those legitimately wronged (which there are a lot of), they are only interested in using sex as a weapon to seize more and more power for ineffectual, weak, dictator wannabes!

    1. Re:Lax network security. by Anonymous Coward · · Score: 1

      Says the guy who likes to watch porn at work on his employer's dime.

    2. Re:Lax network security. by hduff · · Score: 1

      Says the guy who likes to watch porn at work on his employer's dime.

      Oh, snap . . .

      --
      "I believe in Karma. That means I can do bad things to people all day long and I assume they deserve it." : Dogbert
    3. Re:Lax network security. by gerald.edward.butler · · Score: 1

      Says the ANONYMOUS CHILD MOLESTER who sexually assaults prepubescent boys! Stay anonymous so you can hide your child molestation habits. What's your name? Chester the Molester!

    4. Re:Lax network security. by Zontar+The+Mindless · · Score: 1

      Were you actually frothing at the mouth when you typed that?

      --
      Il n'y a pas de Planet B.
    5. Re:Lax network security. by gerald.edward.butler · · Score: 1

      Do you actually have his dick-froth in your mouth? Gross.

    6. Re:Lax network security. by gerald.edward.butler · · Score: 1

      What the fuck do UID's have to with anything? Is that the best you can do with your Ad-Hominem attacks. Because I won't accept the bullshit Ad-Hominem attacks and attack back at a bunch of worthless pricks who don't even have the courage to name themselves when speaking that means I'm proving your point? Fuck you. You have no logical or rational reasoning whatsoever. Look who is being attacked by AC's. I didn't attack them first. So fuck you. Fuck your 4-digit UID. It would've been better if your mother had used and IUD.

      I am sick and fucking tired of both sides of the political spectrum and all their bullshit. As far as I'm concerned the whole fucking country needs burned to the ground. Having served in the military, If I had to do it again, I wouldn't. The people of this country (including yourself) are not worthy of having been served. So fuck off and kill yourself you lousy fucking prick!

    7. Re:Lax network security. by gerald.edward.butler · · Score: 1

      Fuck off child molester. When you are ready to name yourself, we'll talk. Until then, fuck off ANONYMOUS CHILD MOLESTER!

  26. Re:Single Rogue Host by Anonymous Coward · · Score: 1

    Just because the idiot is a government employee doesn't make him any worse than the millions of employees in corporations and schools who also watch porn. I agree the network should be more locked down, but that assumes one is able to hire higher quality sysadmins, and most likely the gov't can't afford to pay them. (remember, our current fearless leader thinks we ought to reduce the size of our federal government.)

  27. Re:Single Rogue Host by ThurstonMoore · · Score: 1

    Well we know his infected phone was Linux based, what's your point?

  28. Ad Blockers by kackle · · Score: 1

    Would ad blocker plug-ins have prevented this?

  29. Re:Yeah, this happens. Not just in the USG either. by Bob+the+Super+Hamste · · Score: 1

    Most times we give folks the benefit of a doubt the 1st time in case it's some porn ad something on an otherwise "okay" site (gray, but not really a policy violation)

    Had that happen to me once, but it wasn't a bad ad but a bad search result. Was looking for how to solve some SQL Server issue clicked on a link that looked like it had relevant info, but nope, porn site. My boss was behind me and saw it and asked what I was doing. I explained to her the problem I was working on showed the search result page with the relevant search result I clicked on and then showed that it went to the porn site instead. Thankfully it was at a small company so there was not a HR battle to be had.

    --
    Time to offend someone
  30. Lighten Up by hduff · · Score: 1

    He's helping pay for repairing potholes and clearing snow from streets . . .

    --
    "I believe in Karma. That means I can do bad things to people all day long and I assume they deserve it." : Dogbert
  31. Re:public shaming by media by hduff · · Score: 1

    So now slashdot has brought it to the front to publicly shame the individual?

    Trial by media... shame on you slashdot.

    Welcome to the Internet. Have a good time!

    --
    "I believe in Karma. That means I can do bad things to people all day long and I assume they deserve it." : Dogbert
  32. Re:Yeah, this happens. Not just in the USG either. by hduff · · Score: 1

    I mean, is this guy sitting there at his desk with a huge boner and then sneaking off to the loo for a quick wank?

    "Huge boner"?

    I think you give him too much credit.

    --
    "I believe in Karma. That means I can do bad things to people all day long and I assume they deserve it." : Dogbert
  33. Re:Yeah, this happens. Not just in the USG either. by hduff · · Score: 1

    Lots of malware comes down in the form of a "video codec" or plugin you need to watch the media. It's just awful.

    LOL, and that is why I do all of my porn watching on a FreeBSD VM with a locked down Firefox which doesn't allow scripts or plugins.

    No way in hell I trust a bloody porn site to not be infested with malicious shit.

    YouDaRealMVP.jpg

    --
    "I believe in Karma. That means I can do bad things to people all day long and I assume they deserve it." : Dogbert
  34. Re:Yeah, this happens. Not just in the USG either. by Da+w00t · · Score: 1

    If you work computer security for any company of decent size...

    And just how many people is that, precisely? 20? 50? 100? 1000?

    I really don't see how that is relevant, do you expect me to quote a scientific study that shows MTTP (mean time to pr0n)? "decent size" was very obviously a generalization.

    --

    da w00t. mtfnpy?
  35. Re: Single Rogue Host by cayenne8 · · Score: 4, Interesting

    Why would you fire the employee who committed a relatively unimportant and meaningless act when the real problem is in the security system, or even in the overtly infected porn industry?

    Your priorities are entirely wrong, as usual for somebody who lacks perspective.

    Seriously?

    My base perspective is...the idiot is getting paid my MY (and yours) tax dollars, and I"m guessing the job description says nothing about surfing porn on the federal dollar?

    Are you telling me that someone that did this very same thing in the private sector wouldn't be canned in a new york minute??

    Seriously...are you saying you think it is acceptable to surf porn at work?

    Sure, better security, that's a given, but you think this person should not be held directly responsible for doing something that EVERYONE knows they are not supposed to do at work on the clock on work computers.

    Hell, government computers come with all kinds of warnings the second you try to log onto them, it isn't like anyone on a federal computer wouldn't know this a forbidden thing to do.....

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  36. Re:Single Rogue Host by lactose99 · · Score: 1

    This is, sadly, all too common.

    --
    Fully licensed blockchain psychiatrist
  37. Re: Single Rogue Host by cayenne8 · · Score: 1

    Hazarding a guess here, you're posting this from your work PC/laptop aren't you?

    Nope.

    And even if I were...it isn't pr0n.

    And, work policies allow for some personal web time during the work day, as long as it isn't against company policies such as viewing pr0n, etc.

    Most workplaces allow some person computer time, but I don't know of any that allow pr0n surfing on the clock on work equipment...save maybe at FB searching for bad content to remove.

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  38. Oh the irony! by mark_reh · · Score: 1

    Of course he was watching porn! He worked at the EROS center!

  39. Re:Yeah, this happens. Not just in the USG either. by mark-t · · Score: 1

    I was simply curious as to whether or not the places I have worked in the past decade may not be large enough, or if your generalization of "any company" was, in fact, an overgeneralization.

  40. Should not be possible by TomGreenhaw · · Score: 1

    Jeesh - can't our government use a firewall with content filtering???

    --
    Greed is the root of all evil.
  41. Re: Single Rogue Host by mhail · · Score: 2

    Old IT admin here. We had a user that was not only downloading gigs at work to his work laptop, he was also using his processor at 100% for 8 hours a day. When we investigated, he was downloading gigs of regular porn and using his work computer to process them into "3D" like google street view. ALL DAY for weeks until we noticed. Dude got shit canned real fast. Higher ups just wanted to know if it was ALSO anything illegal. Got paid to watch his 3D porn for "research"

  42. Re: Single Rogue Host by Kiaser+Zohsay · · Score: 1

    If it ain't broke don't fix it, but broke is highly subjective. It might happen slowly, but at some point the reliance on outdated, unsupported, insecure tech crosses the threshold into broke territory, and your frog gets boiled.

    --
    I am not your blowing wind, I am the lightning.
  43. Re: Single Rogue Host by doesnothingwell · · Score: 1

    but I don't know of any that allow pr0n surfing on the clock on work equipment...

    My old boss just told me to - Put it on the server and send me a link.

    --
    They can have my command prompt when they pry it from my cold dead fingers.
  44. Re:Single Rogue Host by TomGreenhaw · · Score: 1

    With less than a 2% usage rate for Linux on total desktops out there (quick google search), there is little doubt is was Windows.

    For this to occur, there couldn't have been a firewall with content filtering, anti-virus, or likely even a patch management policy.

    For gross network security management negligence like this, any operating system would likely have been compromised.

    --
    Greed is the root of all evil.
  45. Re:Single Rogue Host by PmanAce · · Score: 1

    Android is not windows based you idiot or are you trolling and leaving key information out?

    --
    Tired of my customary (Score:1)
  46. Re:Single Rogue Host by hey! · · Score: 1

    Securing hosts from other, rogue hosts doesn't do much to protect them if the attack vector is a rogue user.

    This is a data management agency and if you compromise the right user's devices those devices can be used to launch attacks on many hosts.

    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
  47. Re:Yeah, this happens. Not just in the USG either. by mhail · · Score: 1

    That's all true but an addict should know the difference between cellular data and company wifi.

  48. Re:Single Rogue Host by poptix · · Score: 1

    If he had so much time to surf porn at work, and none of his superiors noticed, clearly they should have all been part of that reduction of government.

    --
    Just because you disagree doesn't mean it's not true.
  49. Re:Randy Marsh Strikes Again by Outta_the_way_peck! · · Score: 1

    It was a ghost!

  50. Re: Single Rogue Host by saloomy · · Score: 1

    Clearly at $3t and with its ability to afford to pay people to watch porn, it needs to be reduced. He was stealing from tax payers.

  51. Lack of insight on how to lock computers down. by Darkk · · Score: 1

    Most government entities don't have a clue on their network infrastructure let alone on locking the computers down. Too many different standards and different ways of their networks are built. Guess how many system admins come and go over the years without an once of documentation. Router passwords changed and no one seems to know them. Since no one bother to enforce industry standards of best practices this is what got them.

    Best they could do in the interim is enforce policy rules on the firewall to disallow porn sites and block unauthorized VPN connections (this can be done via the application level on the firewall). Also keep eye on access logs and fetch keywords. Since neither one of them are used is a sign of lazy admins.

  52. Re: Single Rogue Host by myth24601 · · Score: 1

    My base perspective is...the idiot is getting paid my MY (and yours) tax dollars, and I"m guessing the job description says nothing about surfing porn on the federal dollar?

    .
    Maybe he was working on a government study of Pr0N use when monkeys are given a computer. It could happen, I have seen governments study stupider stuff.

    --
    No matter where you go, there you are.
  53. Re:Happens probably a lot by dissy · · Score: 1

    Many security experts say the weakest link is the employee who does stupid things. But let's also consider the amount of wasted time as well. If its not porn, its shopping, social sites, or other non job web use

    Two points to that.

    One, shopping sites (at least such as Amazon and the like) in my experience actually have far more benefits than not to allow.

    I commonly see and hear of people doing their grocery shopping on their 3pm break to line up with 2 hour prime delivery for when they get home.
    Those who have managers that disallow it have a *far* higher rate of requests to leave a full hour early to do the same shopping physically.

    That's the difference between a quarter sized chunk of time the employee is legally entitled to not working during, vs a full hour of pay adjustment with lack of that hours productivity.

    Other than that one item on your list however I do agree the rest are at best huge time wasters and at worse an infection method and workplace disruption.

    The second point however is a bit more general. While there are certainly technical steps one can take to at least protect from malware and known bad websites, for the most part such time wasters (think social media) are by far more of a people problem than a technical one, and need to be solved accordingly.

    Locking things down does have an effect on morale to people who can act like adults and behave themselves. This is harder to measure but does exist, and at the end of the day it comes at the cost of attempting and ultimately failing to punish the time waster with ineffective technical means.

    Ever hear the old "standing around the water cooler telling hour long stories" meme?
    That's the thing, time wasters will always find a way to waste time, and it doesn't need to be by technical means.
    This is a problem with the person that needs addressed, not with the technology we run.
    If a person is not putting in the hours they are being paid for, that is the problem, no matter the reason for it.
    If a person is paid for an end result and not delivering, that is the problem, no matter the reason for it.
    This is true no matter if it's wasting time on facebook or wasting time hovering around the break room water cooler, and that fact alone shows this isn't an IT/technical problem to fix.

    Spending IT time and resources fixing one tiny avenue of wasting time will not fix all the other ways to do it, and will not fix the problem which is the person wasting time. It simply costs more for nearly zero benefit.

    Food for thought.

  54. Re:Single Rogue Host by guruevi · · Score: 1

    The Android seems to have been a carrier of the data. Not how the Windows host got infected, as far as I know there isn't any malware that infects both Android and Windows

    --
    Custom electronics and digital signage for your business: www.evcircuits.com
  55. Give him a break by reboot246 · · Score: 1

    At least he was doing something, which is more than you can say for most Federal workers.

  56. Re: Single Rogue Host by guruevi · · Score: 2

    Old IT admin here but also knowledgeable about legal frameworks. You shouldn't be investigating anyone for anything illegal, you don't have the knowledge, legal standing or tools for proper forensic examination. If you did find something, the evidence would be declared botched by any first year attorney and a mistrial would be declared, you may even become liable yourself.

    If your employer wants to know if your employee did something illegal, get the right people involved to do the right kind of investigation. That means third party or police/government agency.

    --
    Custom electronics and digital signage for your business: www.evcircuits.com
  57. Re: Single Rogue Host by morethanapapercert · · Score: 3
    I'm former IT as well, but from Canada, so the actual laws are different, but I think the underlying legal principles should be very comparable.

    With that in mind, let me say that the duly appointed sysadmin or anyone from the IT staff can look at things without it being considered to "taint" evidence, otherwise we'd never be able to convict the sick (and stupid) people who take their computer into Best Buy for repair while leaving a folder full of child pornography.

    What I was taught in school, and instructed to do at several jobs (including one internship at the provincial gov't level) was this: Do your job, which may include examining data a user has stored on their work issued equipment. IF you see anything that you think is illegal or even questionable, tell the boss and call the cops. Do not touch the machine any further. Do not even shut it down. The boss will then see to it that physical access to the device is restricted and the police will show up to handle the disconnection from the network and possible shut down. (did you know the police actually have a device that lets them fake a network connection and keep a desktop machine fully powered while driving it across town? I found the bit where they slipped a probe between plug and outlet to seamlessly transfer power source from wall to battery pack particularly fascinating).

    The reason for this policy is three fold:

    1) A lot of successful prosecutions, especially for illegal porn, rely on happen-stance. A tech stumbling over something, a creep forgets to log out and his wife finds it, whatever. As long as the discoverer can swear in court that they just stumbled across it and did nothing that would alter the data, then the data is still admissible.

    2) The police just do NOT have the manpower to handle every "we fired John for surfing porn at work, can you come and check his machine to see if he did anything illegal as well?

    3) The report of the discoverer is often the basis for probable cause and issuance of a warrant. If I didn't tell the police I saw something off, they would have no legal basis from which to proceed with an investigation.

    One last thought: Even if a guy does surf or create child porn on the work issued equipment, while sufficient for conviction, it may not always be the sole source of such evidence. Any one making illegal porn on a work machine probably has more of it on his personal machine back home as well. (pedos are also notorious for amassing large collections) Thus, even if the evidence I uncover is not enough to convict on its own, it's still enough to justify warrants and investigation to collect more, better quality evidence.

    --
    I need a wheelchair van for my son. Help me get the word out. https://www.gofundme.com/wheelchair-van-for-jj
  58. Re: Single Rogue Host by guruevi · · Score: 1

    Yes, I agree, you can "stumble across" something but you can't go out and hunt for evidence. If your company is truly worried but has no sufficient proof, get a professional third party forensic investigator (and an attorney to give you advice). Otherwise it's just a suspicion/allegation/gut feeling but in many cases you can't just go out and look for something you suspect.

    I had something similar fairly recently (allegations of sexual harassment with HR-goons subsequently botching the thing) and the CIO simply searched employee email to "resolve" the issue. A civil case ensued and the judge ruled that the company didn't have a clear enough policy on searching email (which just stated "we can search your email" somewhere deep in a trail of related IT policies) and violated the expectation of privacy of those involved.

    --
    Custom electronics and digital signage for your business: www.evcircuits.com
  59. Re:Single Rogue Host by NicBenjamin · · Score: 1

    Presumably he got an Android virus doing stupid shit on his Android phone, and got a Windows virus because he was doing stupid shit on his desktop.

  60. Wait, What? by dcw3 · · Score: 1

    OMG, it wasn't a contractor? Seriously, this is typical government workforce in the US.

    --
    Just another day in Paradise